Firewall Policy
Configuring firewall policies
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
329
•
To create an identity-based firewall policy (non-SSL-VPN)
1
Go to
Firewall > Policy > Policy
and select
Create New
.
2
Configure
Source Interface/Zone
,
Source Address
,
Destination Interface/Zone
,
Destination Address, Schedule,
and
Service
. For more information, see
firewall policies” on page 323
3
In the
Action
field, select
ACCEPT
.
4
Select the
Enable Identity Based Policy
check box.
A table opens below the check box.
5
Select
Add
.
Service
The firewall service or service group that packets must match to trigger this policy.
Profile
The protection profile to apply antivirus, web filtering, web category filtering, spam
filtering, IPS, content archiving, and logging to this policy. You can also create a
protection profile by selecting
Create New
from this list. For more information, see
“Firewall Protection Profile” on page 397
.
Traffic Shaping
The traffic shaping configuration for this policy.
For more information, see
.
Reverse
Direction
Traffic
Shaping
Select to enable the reverse traffic shaping. For example, if the
traffic direction that a policy controls is from port1 to port2, select
this option will also apply the policy shaping configuration to traffic
from port2 to port1.
Log Traffic
If the
Log Allowed Traffic
option is selected when adding an identity-based policy,
a green check mark appears. Otherwise, a white cross mark appears.
Delete icon
Select to remove this policy.
Edit icon
Select to modify this policy.
Firewall
Include firewall user groups defined locally on the FortiGate unit, as well as on
any connected LDAP and RADIUS servers. This option is selected by default.
Directory
Service (FSAE)
Include Directory Service groups defined in
User > User Group
. The groups are
authenticated through a domain controller using Fortinet Server Authentication
Extensions (FSAE). If you select this option, you must install the FSAE on the
Directory Service domain controller. For information about FSAE, see the
. For information about configuring user groups, see
.
NTLM
Authentication
Include Directory Service groups defined in
User > User Group
. If you select this
option, you must use Directory Service groups as the members of the
authentication group for NTLM. For information about configuring user groups,
see
.
Certificate
Certificate-based authentication only. Select the protection profile that guest
accounts will use.
Note:
In order to implement certificate-based authentication,
you must select a firewall service group that includes one of the supported
authentication protocols that use certificate-based authentication. You should also
install the certificate on the network user’s web browser. For more information,
see
Содержание Gate 60D
Страница 678: ...Reports Log Report FortiGate Version 4 0 Administration Guide 678 01 400 89802 20090424 http docs fortinet com Feedback...
Страница 704: ...Index FortiGate Version 4 0 Administration Guide 704 01 400 89802 20090424 http docs fortinet com Feedback...
Страница 705: ...www fortinet com...
Страница 706: ...www fortinet com...